Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

Fake LastPass Authenticator Installer Leverages Microsoft‑Signed Driver to Neutralize Security Software

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-09-22 T 01:33:09 Z | [ 2 MIN READ ]
Fake LastPass Authenticator Installer Leverages Microsoft‑Signed Driver to Neutralize Security Software
2 Min Read
Share

Fake LastPass Authenticator Installer Exploits Microsoft‑Signed Driver

A counterfeit LastPass Authenticator installer circulating on GitHub drops a Windows kernel driver that disables antivirus, endpoint detection and response (EDR) tools before unleashing a password‑stealing payload. Researchers at LastPass and Delphos Labs observed the driver bears a legitimate Microsoft hardware‑compatibility signature, allowing it to bypass Windows driver enforcement. VirusTotal logged ↓ 0 detections at the time of analysis, a stark illustration of trust abuse. Once the driver is loaded, security suites are silently terminated, leaving the system exposed. ‘The attacker’s playbook is simple: neutralize defenses, then harvest credentials,’ said a security analyst in a

private briefing

. The malicious installer masquerades as a legitimate update, prompting users to download and execute it. Microsoft’s signing program, intended for genuine hardware drivers, is being weaponized, raising questions about the vetting process for kernel‑mode code. Reuters reported a surge in similar supply‑chain tricks this year, while Bloomberg highlighted the growing market for signed driver malware. Organizations are urged to enforce strict code‑signing policies and monitor kernel activity. The episode also echoes broader security challenges that have emerged in the wake of the pandemic, when remote work expanded the attack surface.


Reported by: Nova Stirling

Aerospace & Space Tech Correspondent

Global Data Feed

More from this Intel

RatHat malware: AI‑powered Android threat masquerading as Chrome

RatHat malware: AI‑powered Android threat masquerading as Chrome

Sep 22, 2026
Jade Sleet Breaches Indian IT Provider with FLATROOF and ROOFDECK Backdoors

Jade Sleet Breaches Indian IT Provider with FLATROOF and ROOFDECK...

Sep 21, 2026
Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Sep 20, 2026
Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a Massive Supply‑Chain Attack

Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a...

Sep 20, 2026
Gyazo data breach leaks 23.6 million accounts – massive server flaw exposed

Gyazo data breach leaks 23.6 million accounts – massive server...

Sep 19, 2026
Microsoft security patches shatter record with 974 fixes in September

Microsoft security patches shatter record with 974 fixes in September

Sep 19, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.